CVE-2025-31333: Odata meta-data tampering in SAP S4CORE entity
Published Apr 8, 2025
·Updated
SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability is not impacted.
Affected Software
1 affected component
SAP S4CORE
Event History
Apr 8, 2025
CVE Published
via MITRE·07:15 AM
Data Sourced
via MITRE·07:15 AM
DescriptionSeverity
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-31333?
CVE-2025-31333 has a low severity rating as it primarily affects the integrity of the application.
2
How do I fix CVE-2025-31333?
To mitigate CVE-2025-31333, ensure that proper validation and access controls are implemented for OData metadata properties.
3
What impact does CVE-2025-31333 have on data integrity?
CVE-2025-31333 allows attackers to tamper with entity sets, which can compromise the integrity of application data.
4
Is CVE-2025-31333 related to confidentiality issues?
CVE-2025-31333 does not impact confidentiality, as it focuses primarily on data integrity.
5
What applications are affected by CVE-2025-31333?
CVE-2025-31333 affects the SAP S4CORE component of the SAP S/4HANA software.